PCI Security Standards Council Publishes Security Requirements for Software-Based PIN Entry on COTS Devices
Today the PCI Security Standards Council (PCI SSC) announced a new PCI Security Standard for software-based PIN entry on commercial off-the-shelf devices (COTS), such as smartphones and tablets. The PCI Software-Based PIN Entry on COTS (SPoC) Standard provides requirements for developing secure solutions that enable EMV contact and contactless transactions with PIN entry on the merchant’s consumer device using a secure PIN entry application in combination with a Secure Card Reader for PIN (SCRP).
“Mobile point-of-sale (MPOS) solutions have become very popular with smaller merchants for their flexibility and efficiency. MPOS has enabled them to take orders and accept payments on a tablet or smartphone, anytime and anywhere. However, some small merchants in markets that require EMV chip-and-PIN acceptance may have found the costs of investing in hardware prohibitive,” said Aite Group Senior Analyst Ron van Wezel. “With the new PIN entry standard, the PCI Council has responded to market need by specifying the security requirements for allowing PIN entry directly on the mobile touchscreen. This means that merchants can accept payments with just their mobile device and a small, cost efficient card reader connected to it along with a secure PIN entry application. The payment industry will benefit overall from the wider choice in payment acceptance, as it will drive the growth of electronic transactions.”
“The PCI Council has a long history of developing standards for protecting PIN as a verification method in hardware-based solutions. Existing PCI PIN Standards require hardware-based security protection of the PIN,” said PCI SSC Chief Technology Officer Troy Leach. “We are now building on this foundation with a new standard that allows for an alternative approach to secure PIN entry by isolating the PIN from other data and using a new robust set of security controls that extend beyond the physical hardware device itself. The PCI Software-Based PIN Entry Standard gives solution providers and application developers a baseline of security requirements specifically for accepting EMV contact and contactless transactions using software-based PIN entry.”
Key security principles included in the standard’s security and test requirements are:
- Active monitoring of the service, to mitigate against potential threats to the payment environment within the phone or tablet;
- Isolation of the PIN from other account data;
- Ensuring the software security and integrity of the PIN entry application on the COTS device;
- Protection of the PIN and account data using a PCI approved Secure Card Reader for PIN (SCRP).
The Software-Based PIN Entry on COTS Security Requirements are for solution providers to use in designing each part of a complete solution. These requirements are available now on the PCI SSC website.
The Software-Based PIN Entry on COTS Test Requirements outline testing processes for laboratories to use in evaluating solutions against the standard. These will be published in the next month, followed by a supporting program that will list PCI validated solutions on the PCI SSC website for merchant use.
For more information on the new standard, read PCI Perspectives blog post New PCI Software-Based PIN Entry on COTS Standard .
“This standard gives solution providers and application developers a baseline of security requirements for how to securely accept PIN-based transactions on a COTS device, as well as methods to test that security is working, even as updates to the devices and applications occur frequently. PCI validated solutions will meet a robust set of security objectives that have been tested by independent laboratories,” added Leach. “More and more businesses are now accepting payments with smartphones, tablets and other COTS devices, especially within the small business community. The PCI SSC Software-Based PIN Entry Solution listing will provide these merchants with a resource for selecting PIN entry solutions that have been evaluated and tested by payment security laboratories, and their customers will benefit by having the best available protection for their payment data.”
About the PCI Security Standards Council
The PCI
Security Standards Council (PCI SSC) leads a global, cross-industry
effort to increase payment security by providing industry-driven,
flexible and effective data security standards and programs that help
businesses detect, mitigate and prevent cyberattacks and breaches.
Connect with the PCI SSC on LinkedIn.
Join the conversation on Twitter @PCISSC.
Subscribe to the PCI
Perspectives Blog.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: http://www.businesswire.com/news/home/20180124005766/en/
Contact information
PCI Security Standards Council
Mark Meissner, +1-202-744-8557
press@pcisecuritystandards.org
Twitter
@PCISSC
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Venture Global Statement on Shell Arbitration Decision12.8.2025 23:51:00 EEST | Press release
Today, Venture Global issued the following statement in response to the positive tribunal decision on the arbitration proceeding with Shell: “We are pleased with the tribunal’s determination which reaffirms what Venture Global has maintained from the outset--the plain language in our contracts, mutually agreed upon with all of our customers, is clear. We have consistently honored these agreements without exception. Our industry and the investors and lenders who underpin it, all rely on respect for both the sanctity of negotiated contracts and the experienced, objective regulatory and legal bodies that govern it. These principles will ensure our industry remains dynamic, fair and competitive, enabling the innovation and breakthroughs that benefit all market participants and the customers we serve. Venture Global’s unique ability to incrementally export commissioning cargoes during the construction of our facilities has brought LNG to the market years faster than ever before and strength
Celonis Named a Leader in Process Intelligence Software12.8.2025 19:18:00 EEST | Press release
Celonis, a global leader in Process Mining, today announced it has been named a Leader in The Forrester Wave™: Process Intelligence Software, Q3 2025. According to the report, “Celonis is best suited to clients looking for a sophisticated platform that supports enterprise-wide process intelligence and control to transform operations.” Forrester also cited Celonis’ trailblazing role in the category, noting its early adoption of graph databases, an additional object-centric view of process performance, and an extended marketplace of partner-built solutions. “We are honored to be named a Leader in The Forrester Wave: Process Intelligence. This recognition is only possible because of the dedication and commitment of our customers, partners and Celonauts,” said Carsten Thoma, President and Board Director, Celonis. “Enterprise AI is set to reinvent operations. To deliver on its full potential, AI needs to understand how each business runs and how to make it run better. Our Process Intelligen
Empowering Developers to Monetize Anywhere: Xsolla Expands Platform Support for Cross-Platform Direct-to-Consumer Commerce12.8.2025 19:00:00 EEST | Press release
Xsolla, a global commerce company helping developers launch, grow, and monetize their games, announces today a major expansion of its platform support capabilities, reinforcing its position as the premier provider of cross-platform monetization solutions for developers. With the latest SDKs for Windows Stores and the Epic Games Store, a new strategic partnership with Pley, and the launch of the Xsolla Discord Bot, developers can now implement secure, streamlined commerce across PC, mobile, web, and community platforms. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250812673202/en/ (Graphic: Xsolla) Key Platform Expansions Now Available to Developers: SDK for Windows stores PC developers can access flexible monetization tools via Xsolla SDK for Windows Stores, offering seamless checkout flows and cross-platform SKU synchronization for multiplatform titles available on Windows across a variety of game stores. Setup is streaml
Andersen Consulting Expands Digital Transformation Solutions with Future Processing12.8.2025 16:30:00 EEST | Press release
Andersen Consulting announces a Collaboration Agreement with Future Processing, a technology and software consultancy, strengthening the organization’s ability to deliver end-to-end digital solutions. Founded in 2000 in Poland, Future Processing has been successfully delivering advanced IT projects for clients worldwide for over two decades. The company provides a full spectrum of services based on extensive technological expertise and advisory capabilities—from consulting and digital product strategy to custom software development, cloud, data, AI, machine learning, and cybersecurity solutions. Their expertise enables clients to adopt AI, migrate and integrate systems, modernize and scale cloud infrastructure, optimize and manage IT operations, and execute performance-led engineering initiatives. “Through our collaboration with Andersen Consulting, we advance our mission to deliver technology solutions at scale,” said Michał Sztanga, managing director of Future Processing. “Together,
Unity Game Developers Can Now Enable Direct-to-Consumer Monetization With Xsolla’s New SDK12.8.2025 16:00:00 EEST | Press release
Xsolla, a global commerce company helping developers launch, grow, and monetize their games, today announces the launch of an SDK for Unity that expands monetization capabilities for developers using the Unity engine. This new SDK is a part of Xsolla’s continued mission to unlock direct-to-consumer revenue opportunities across all platforms - mobile, PC, and the web - without complex backend work. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250812923531/en/ (Graphic: Xsolla) Whether building a mobile-first title, a PC game, or a browser-based game, Unity developers can now integrate payments, enable in-game purchases, and create custom storefronts without relying on closed platforms. With a fast time-to-market, developers can start selling directly to their players and retain more of their revenue from day one, while maintaining full ownership of the checkout experience, player data, and monetization strategy. Key benefit
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom